NVIDIA has revealed that its GPUs with Confidential Computing (a technology that encrypts and isolates data while it is being processed) are now being used for confidential inference in Apple's Private Cloud Compute (PCC)[1]. PCC previously ran inside Apple's own data centers, but it is now expanding to Google Cloud. Unveiled at Apple's WWDC, the effort is drawing attention as a collaboration in which NVIDIA, Apple, and Google work together to support the next generation of Apple Intelligence.
NVIDIA Blackwell GPUs Power Server-Side Inference for Apple Intelligence
In this collaboration, NVIDIA GPUs handle server-side inference for Apple Foundation Models (the family of foundation models Apple builds in-house)[1]. These models are custom-built jointly by Apple and Google, leveraging the technologies behind Google's "Gemini" family of models.
Specifically, the work uses NVIDIA's Confidential Computing–capable "Blackwell" generation GPUs[1]. They are integrated into Private Cloud Compute's hardware security architecture and run on Google Cloud. The aim is to offload the heavy inference that smartphones and PCs cannot fully handle on their own to the cloud, while still protecting user privacy.
What Is Confidential Computing?
Confidential Computing provides a hardware-level security layer for AI processing[1]. It isolates running workloads (computations in progress) inside a trusted execution environment so that their contents cannot be viewed from the outside.
It also lets systems cryptographically verify that the infrastructure has not been tampered with before any sensitive data is sent to the server[1]. NVIDIA says this mechanism makes it possible to reach a state where, for the end user, "no one, not even the people who built the system, can look at their data or conversations." It is a design that responds to the worry many people feel when entrusting AI processing to the cloud: the fear that someone might see their exchanges.
Four Mechanisms Underpinning Privacy and Trust
NVIDIA, describing Confidential Computing as an embodiment of its commitment to trustworthy AI, highlights four key capabilities[1].
The first is hardware-rooted trust, which helps establish that systems are running on genuine, untampered NVIDIA GPUs. The second is encrypted communication paths that protect data as it moves between components. The third is remote attestation, which lets software verify the security state of the platform before releasing sensitive data. And the fourth is the ability to run AI inference and training without sacrificing GPU performance, even while these protections are in effect.
These capabilities are said to be growing more important for AI services that must handle sensitive information while maintaining strong privacy controls.
The Shift Toward Combining On-Device and Cloud Processing
Behind the adoption of Confidential Computing at this scale is a change in how AI experiences are delivered[1]. Recent AI increasingly combines on-device processing with cloud-based processing to complete tasks, driving up demand for high-performance server-side inference.
At the same time, the more processing moves to the cloud, the stricter the requirements for data protection become. The idea that hardware-embedded security is the key to balancing performance and privacy is spreading across AI infrastructure as a whole. With three major companies—NVIDIA, Apple, and Google—joining forces around concrete products, this looks like a case that symbolizes the trend.
Summary
NVIDIA announced that its Confidential Computing–capable Blackwell GPUs have been adopted in Apple's Private Cloud Compute and will support its expansion to Google Cloud[1]. The effort aims to run server-side inference for Apple Foundation Models in a way that lets no one peer into user data. As AI that spans device and cloud becomes the norm, the question of how to balance performance and privacy looms large. As one answer, the role of hardware-rooted Confidential Computing looks set to grow even further.
Source: https://blogs.nvidia.com/blog/nvidia-confidential-computing-apple-private-cloud-compute/
